CVE-2011-2524
libsoup: SoupServer directory traversal flaw
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.
Una vulnerabilidad de salto de directorio en la soup-uri.c en SoupServer en libsoup antes de v2.35.4 permite a atacantes remotos leer archivos de su elección a través de un %2e%2e (punto punto) en la URI.
This GLSA contains notification of vulnerabilities found in several Gentoo packages which have been fixed prior to January 1, 2012. The worst of these vulnerabilities could lead to local privilege escalation and remote code execution.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2011-06-15 CVE Reserved
- 2011-08-31 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://git.gnome.org/browse/libsoup/tree/NEWS | X_refsource_confirm | |
http://secunia.com/advisories/47299 | Third Party Advisory | |
http://www.securitytracker.com/id?1025864 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.gnome.org/show_bug.cgi?id=653258 | 2012-02-02 |
URL | Date | SRC |
---|---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063431.html | 2012-02-02 | |
http://www.debian.org/security/2011/dsa-2369 | 2012-02-02 | |
http://www.redhat.com/support/errata/RHSA-2011-1102.html | 2012-02-02 | |
http://www.ubuntu.com/usn/USN-1181-1 | 2012-02-02 | |
https://access.redhat.com/security/cve/CVE-2011-2524 | 2011-07-28 | |
https://bugzilla.redhat.com/show_bug.cgi?id=720509 | 2011-07-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | <= 2.35.3 Search vendor "Gnome" for product "Libsoup" and version " <= 2.35.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.0 Search vendor "Gnome" for product "Libsoup" and version "2.0" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2 Search vendor "Gnome" for product "Libsoup" and version "2.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.0 Search vendor "Gnome" for product "Libsoup" and version "2.2.0" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.1 Search vendor "Gnome" for product "Libsoup" and version "2.2.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.2 Search vendor "Gnome" for product "Libsoup" and version "2.2.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.3 Search vendor "Gnome" for product "Libsoup" and version "2.2.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.4 Search vendor "Gnome" for product "Libsoup" and version "2.2.4" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.5 Search vendor "Gnome" for product "Libsoup" and version "2.2.5" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.6 Search vendor "Gnome" for product "Libsoup" and version "2.2.6" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.6.1 Search vendor "Gnome" for product "Libsoup" and version "2.2.6.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.7 Search vendor "Gnome" for product "Libsoup" and version "2.2.7" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.91 Search vendor "Gnome" for product "Libsoup" and version "2.2.91" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.92 Search vendor "Gnome" for product "Libsoup" and version "2.2.92" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.93 Search vendor "Gnome" for product "Libsoup" and version "2.2.93" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.94 Search vendor "Gnome" for product "Libsoup" and version "2.2.94" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.95.1 Search vendor "Gnome" for product "Libsoup" and version "2.2.95.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.96 Search vendor "Gnome" for product "Libsoup" and version "2.2.96" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.97 Search vendor "Gnome" for product "Libsoup" and version "2.2.97" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.98 Search vendor "Gnome" for product "Libsoup" and version "2.2.98" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.99 Search vendor "Gnome" for product "Libsoup" and version "2.2.99" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.100 Search vendor "Gnome" for product "Libsoup" and version "2.2.100" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.101 Search vendor "Gnome" for product "Libsoup" and version "2.2.101" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.102 Search vendor "Gnome" for product "Libsoup" and version "2.2.102" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.103 Search vendor "Gnome" for product "Libsoup" and version "2.2.103" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.2.104 Search vendor "Gnome" for product "Libsoup" and version "2.2.104" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.3.0.1 Search vendor "Gnome" for product "Libsoup" and version "2.3.0.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.3.2 Search vendor "Gnome" for product "Libsoup" and version "2.3.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.3.4 Search vendor "Gnome" for product "Libsoup" and version "2.3.4" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.4.0 Search vendor "Gnome" for product "Libsoup" and version "2.4.0" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.4.1 Search vendor "Gnome" for product "Libsoup" and version "2.4.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.23.1 Search vendor "Gnome" for product "Libsoup" and version "2.23.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.23.6 Search vendor "Gnome" for product "Libsoup" and version "2.23.6" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.23.91 Search vendor "Gnome" for product "Libsoup" and version "2.23.91" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.23.92 Search vendor "Gnome" for product "Libsoup" and version "2.23.92" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.24.0.1 Search vendor "Gnome" for product "Libsoup" and version "2.24.0.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.24.1 Search vendor "Gnome" for product "Libsoup" and version "2.24.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.25.2 Search vendor "Gnome" for product "Libsoup" and version "2.25.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.25.3 Search vendor "Gnome" for product "Libsoup" and version "2.25.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.25.4 Search vendor "Gnome" for product "Libsoup" and version "2.25.4" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.25.5 Search vendor "Gnome" for product "Libsoup" and version "2.25.5" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.25.91 Search vendor "Gnome" for product "Libsoup" and version "2.25.91" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.26.0 Search vendor "Gnome" for product "Libsoup" and version "2.26.0" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.26.1 Search vendor "Gnome" for product "Libsoup" and version "2.26.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.27.1 Search vendor "Gnome" for product "Libsoup" and version "2.27.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.27.2 Search vendor "Gnome" for product "Libsoup" and version "2.27.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.27.4 Search vendor "Gnome" for product "Libsoup" and version "2.27.4" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.27.5 Search vendor "Gnome" for product "Libsoup" and version "2.27.5" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.27.90 Search vendor "Gnome" for product "Libsoup" and version "2.27.90" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.27.91 Search vendor "Gnome" for product "Libsoup" and version "2.27.91" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.27.92 Search vendor "Gnome" for product "Libsoup" and version "2.27.92" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.28.0 Search vendor "Gnome" for product "Libsoup" and version "2.28.0" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.28.1 Search vendor "Gnome" for product "Libsoup" and version "2.28.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.29.3 Search vendor "Gnome" for product "Libsoup" and version "2.29.3" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.29.5 Search vendor "Gnome" for product "Libsoup" and version "2.29.5" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.29.6 Search vendor "Gnome" for product "Libsoup" and version "2.29.6" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.29.90 Search vendor "Gnome" for product "Libsoup" and version "2.29.90" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.29.91 Search vendor "Gnome" for product "Libsoup" and version "2.29.91" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.30.0 Search vendor "Gnome" for product "Libsoup" and version "2.30.0" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.30.1 Search vendor "Gnome" for product "Libsoup" and version "2.30.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.31.2 Search vendor "Gnome" for product "Libsoup" and version "2.31.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.31.6 Search vendor "Gnome" for product "Libsoup" and version "2.31.6" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.31.90 Search vendor "Gnome" for product "Libsoup" and version "2.31.90" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.31.92 Search vendor "Gnome" for product "Libsoup" and version "2.31.92" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.32.0 Search vendor "Gnome" for product "Libsoup" and version "2.32.0" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.32.1 Search vendor "Gnome" for product "Libsoup" and version "2.32.1" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.32.2 Search vendor "Gnome" for product "Libsoup" and version "2.32.2" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.33.4 Search vendor "Gnome" for product "Libsoup" and version "2.33.4" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.33.5 Search vendor "Gnome" for product "Libsoup" and version "2.33.5" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.33.6 Search vendor "Gnome" for product "Libsoup" and version "2.33.6" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.33.90 Search vendor "Gnome" for product "Libsoup" and version "2.33.90" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.33.92 Search vendor "Gnome" for product "Libsoup" and version "2.33.92" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.34.0 Search vendor "Gnome" for product "Libsoup" and version "2.34.0" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Libsoup Search vendor "Gnome" for product "Libsoup" | 2.34.1 Search vendor "Gnome" for product "Libsoup" and version "2.34.1" | - |
Affected
|